Decidim: JWT-backed authentication can be replayed across organizations (CVE-2026-45414)
Decidim versions prior to 0.31.5 have a vulnerability where JSON Web Tokens (JWTs) issued for one organization can be replayed against another organization's API. This allows unauthorized access to sensitive participant details and mutation paths intended for that other organization. The issue arises because JWT authentication is not sufficiently bound to the host organization context, enabling cross-organization token reuse.
AI Analysis
Technical Summary
The vulnerability in Decidim involves insufficient binding of JWT-backed API authentication to the organization context. A JWT issued for an account in Organization 1 can be used to authenticate API requests against Organization 2's API, allowing access to admin-only GraphQL fields such as participantDetails and mutation paths like proposal.answer. This trust boundary violation enables an attacker with a valid JWT from one organization to read sensitive data from another organization. The problem affects API user authentication similarly. The root cause is that the current host selects the organization context but the JWT authentication does not verify that the token belongs to that organization. This vulnerability is tracked as CVE-2026-45414 and is classified under CWE-287 (Improper Authentication).
Potential Impact
An attacker with a JWT issued for one organization can replay that token against another organization's API, gaining unauthorized read access to sensitive participant personal data and the ability to invoke certain mutation operations. This breaks access control boundaries between organizations, potentially exposing confidential information and allowing unauthorized actions within other organizations' contexts. The CVSS vector indicates network attack vector, low attack complexity, requires privileges, no user interaction, scope changed, high confidentiality impact, low integrity impact, and no availability impact.
Mitigation Recommendations
A fix is available in Decidim versions 0.31.5 and later, as indicated by the referenced pull requests (https://github.com/decidim/decidim/pull/16673 and https://github.com/decidim/decidim/pull/16756). Users should upgrade to version 0.31.5 or later to remediate this issue. As a workaround, disabling JWT credentials via the system panel (/system) can prevent exploitation until the patch is applied.
Decidim: JWT-backed authentication can be replayed across organizations (CVE-2026-45414)
Description
Decidim versions prior to 0.31.5 have a vulnerability where JSON Web Tokens (JWTs) issued for one organization can be replayed against another organization's API. This allows unauthorized access to sensitive participant details and mutation paths intended for that other organization. The issue arises because JWT authentication is not sufficiently bound to the host organization context, enabling cross-organization token reuse.
CVSS v3.1
Score 8.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Decidim involves insufficient binding of JWT-backed API authentication to the organization context. A JWT issued for an account in Organization 1 can be used to authenticate API requests against Organization 2's API, allowing access to admin-only GraphQL fields such as participantDetails and mutation paths like proposal.answer. This trust boundary violation enables an attacker with a valid JWT from one organization to read sensitive data from another organization. The problem affects API user authentication similarly. The root cause is that the current host selects the organization context but the JWT authentication does not verify that the token belongs to that organization. This vulnerability is tracked as CVE-2026-45414 and is classified under CWE-287 (Improper Authentication).
Potential Impact
An attacker with a JWT issued for one organization can replay that token against another organization's API, gaining unauthorized read access to sensitive participant personal data and the ability to invoke certain mutation operations. This breaks access control boundaries between organizations, potentially exposing confidential information and allowing unauthorized actions within other organizations' contexts. The CVSS vector indicates network attack vector, low attack complexity, requires privileges, no user interaction, scope changed, high confidentiality impact, low integrity impact, and no availability impact.
Mitigation Recommendations
A fix is available in Decidim versions 0.31.5 and later, as indicated by the referenced pull requests (https://github.com/decidim/decidim/pull/16673 and https://github.com/decidim/decidim/pull/16756). Users should upgrade to version 0.31.5 or later to remediate this issue. As a workaround, disabling JWT credentials via the system panel (/system) can prevent exploitation until the patch is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-r3v7-5x4c-c69q
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-45414"]
- Ecosystems
- ["RubyGems"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6a55ffbe68715ace432fb772
Added to database: 07/14/2026, 09:22:06 UTC
Last enriched: 07/14/2026, 10:02:00 UTC
Last updated: 07/31/2026, 12:27:30 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.